Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
qyvora-anansi — Terminal-first attack surface intelligence engine. Built for speed, portability, and raw technical signal. | Kitploit
Tools/GitHubGitHub/qyvora/qyvora-anansi
OSINT (Open Source Intelligence)ReconnaissanceVulnerability ScannersNetwork MappingVulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration TestingSubdomain Enumeration
4201 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubqyvora/qyvora-anansi

qyvora-anansi

Terminal-first attack surface intelligence engine. Built for speed, portability, and raw technical signal.

View RepositoryWebsite

             ;                  &              
           ;;                    ;&            
          ;;;                    ;;;           
     ;    ;;;                    ;;;    ;      
     ;;;  ;;;        ;   ;;      ;;;   ;;;     
     ;;;;  ;;;;   ;;; && ;;;   ;;;;   ;;;;     
      ;;;;   ;;;; ;;;;;;;;;; ;;;;    ;;;;      
        ;;;;;;;;; ;;;;;;;;;;;;;;;; ;;;;;;;;;    
            &;;;;;;;;;;;;$x;;;;;;;;;;;;         
           ;;;;;;;;;;&&&+++&&&;;;;;;;;;;;       
     ;;;;;;;;;  ;;;&&+&&&&&+&&;;;  ;;;;;;;;;;  
     ;;;&    ;; ;;;&+&&&&&&&+&&;;; ;;    &;;;  
     ;;;   ;;;;  ;;;&&+&&&&&&+&;;; ;;;;   ;;;  
     ;;;   ;;;   ;;;;&&++&++++&&;;  ;;;   ;;;  
      ;;   ;;;    ;;;;;;;;;;;&&&&;  ;;;   ;;   
      ;;   ;;;      ;;;;;;;;;;;;;;  ;;;   ;;   
       ;   ;;;        ;;;;;;;;;;    ;;;   ;    
           &;;           ;;;;       ;;&        
             ;;           ;;       ;;;          
               ;                 ;             
  

ANANSI CLI

Attack Surface Intelligence Engine — Terminal Edition


Built by QYVORA OffSec — Tamale, Ghana


Release License Go Platform

anansi target.com
anansi scan target.com
anansi target.com --verbose
anansi target.com --deep
anansi target.com -o json > results.json
anansi target.com --modules discovery,tls,takeover
  

Only scan targets you own or have explicit written permission to test.

What it does

ANANSI CLI is a terminal-first attack surface recon tool for pentesters and bug bounty hunters. Give it a domain — it runs a full ten-phase intelligence and exploitation pipeline and prints raw technical output you can act on immediately.

By default, ANANSI filters out the noise and only displays found assets (e.g., live subdomains, active HTTP/HTTPS hosts, successful TLS certificates, missing security headers on live URLs, exposed paths, and confirmed takeovers). This keeps your terminal clean. If you want to see all attempted checks, including dead subdomains, failed connections, and unchecked endpoints, simply enable the verbose flag (-v/--verbose).

PhaseModuleWhat it finds
01DISCOVERYSubdomains via crt.sh CT logs + DNS brute-force wordlist
02PROBELive HTTP/HTTPS hosts — status codes, servers, redirect chains, titles
03TLSCertificate expiry, SANs, protocol version, cipher, self-signed detection
04HEADERSMissing security headers, CORS misconfigurations
05PATHSExposed files — .env, .git, configs, admin panels, backups, API docs
06TECH-STACKDeep audit of detected platforms — version detection, WordPress plugins/themes, XML-RPC, user enumeration, config backups, known-vulnerable version matching
07TAKEOVERDangling CNAMEs pointing to unclaimed cloud services
08OSINTEmails, phone numbers, employees, WHOIS registrant data
09CHAINAssembles findings into multi-step exploit paths (low → high → critical) with per-step exploitation techniques
10EXPLOITActively proves exploitable findings against the authorized target with live HTTP request/response evidence

Performance & Architecture

  • Native Go DNS Resolver: Bypasses slow cgo-blocked system lookups using pure Go goroutines.
  • Shared Connection Pool: A single process-wide HTTP transport with keep-alives is reused across every phase and every module, so TCP + TLS handshakes happen once per host instead of once per request.
  • TTL DNS Cache: Resolved subdomains are cached for 60s, so recursive/mutation/TLS-SAN phases never re-query the resolver for the same name.
  • Fixed Worker Pools: Paths, discovery, probe, and techstack all run on fixed worker pools (one goroutine per --threads, jobs pulled from a channel). No goroutine-per-job churn — even an 8,000+ rule path sweep stays at stable concurrency.
  • Concurrent Probing: HTTP Probes, TLS analyses, and Security Header checks are fully parallelized.
  • Smart Takeover Filtering: Targets only subdomains with verified dead CNAME records.
  • Parallel Exposed Path Probing: Custom 404 baselines fetched concurrently; the deep-audit module adds a soft-404 baseline so catch-all servers don't produce false positives.
  • Version reuse: the tech-stack module reads CMS versions from generator meta tags and static-asset query strings already present in the homepage body, and discovers WordPress plugins from the same body — minimising extra requests.
  • robots.txt mining: every live host's robots.txt Allow/Disallow entries are turned into extra path probes, surfacing intentionally-hidden directories for one extra request per host.

Tech-Stack Deep Audit

When a host is fingerprinted as WordPress, Drupal, Joomla, Magento, Ghost, Moodle, MediaWiki, Laravel, or another platform, ANANSI descends that stack instead of stopping at the surface:

Download Tool